Malware Quarantine and Farbar files Part 1
Here are the requested files
Malware scan history from 7/12/2014 (I also ran the program earlier and can send a file from 7/6/14 if needed.)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 7/12/2014
Scan Time: 12:33:45 PM
Logfile:
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.12.05
Rootkit Database: v2014.07.09.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: admin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 307447
Time Elapsed: 18 min, 44 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 6
PUP.Optional.Adpeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\yewimmxqbs64, No Action By User, [cdd8782699e29e9856507a98ad57a15f],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, No Action By User, [4362c7d74f2c91a501622da029d956aa],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\rrsavings, No Action By User, [b6efcfcf186387afec75ede0da28d12f],
PUP.Optional.ConduitSearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, No Action By User, [aff63a646813f541184415deac57be42],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3773765143-1762522670-3504364941-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\rrsavings, No Action By User, [5b4a544ab1ca9a9ce08603ca27dbec14],
Adware.Adpeak, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\yewimmxqbs64, Quarantined, [7530a9f5bebddc5a3900f0954db71ce4],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings, No Action By User, [a401bde1bac1b28429126c3dff038779],
Files: 7
PUP.Optional.Trovi.A, C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\l4htek0o.default\searchplugins\trovi-search.xml, No Action By User, [b4f119853d3eb77f27f6eeda59a9c040],
PUP.Optional.Adpeak.A, C:\Program Files\002\yewimmxqbs64.exe, No Action By User, [cdd8782699e29e9856507a98ad57a15f],
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings\uninstaller.exe, No Action By User, [a401bde1bac1b28429126c3dff038779],
PUP.Optional.Trovi.A, C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\l4htek0o.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "http://www.trovi.com/?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=MD64D040E-6849-4FC2-B545-01AC5DF05EED&SearchSource=55&CUI=&UM=6&UP=SP5B861986-9E69-429F-86B4-65C97A6D8774&SSPV=")

, No Action By User,[7d28910dea914ee885829933eb1956aa]
PUP.Optional.Trovi.A, C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\l4htek0o.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "http://www.trovi.com/?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=MD64D040E-6849-4FC2-B545-01AC5DF05EED&SearchSource=69&CUI=&SSPV=&Lay=1&UM=6&UP=SP5B861986-9E69-429F-86B4-65C97A6D8774")

, No Action By User,[e2c3b2ec2e4d8babb55321ab93710af6]
Adware.Adpeak, C:\Program Files\002\yewimmxqbs64.exe, Quarantined, [7530a9f5bebddc5a3900f0954db71ce4],
Trojan.Zbot.FWI, C:\Users\admin\Downloads\Label_US_Centreville_20120.zip, Quarantined, [cbdae8b6fd7ef0464f5a76229f6211ef],
Physical Sectors: 0
(No malicious items detected)
(end)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by admin (administrator) on ADMIN-THINK on 20-07-2014 08:17:15
Running from C:\Users\admin\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(UPEK Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Storage Appliance Corp.) C:\ProgramData\OfficeGuardianV2N\UACProxy.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Storage Appliance Corporation) C:\ProgramData\OfficeGuardianV2N\Reminder\SacNetAgent.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Storage Appliance Corp.) C:\ProgramData\OfficeGuardianV2N\Reminder\SacReminder.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(PIXELA CORPORATION) C:\Program Files (x86)\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(PFU LIMITED) C:\Windows\SSDriver\fi5110\SsWiaChecker.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\System Update\SUService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11049576 2010-07-15] (Realtek Semiconductor)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1928976 2010-03-05] (Intel(R) Corporation)
HKLM\...\Run: [TPHOTKEY] => C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [69568 2009-12-21] (Lenovo Group Limited)
HKLM\...\Run: [TpShocks] => TpShocks.exe
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [62312 2010-04-20] (Lenovo Group Limited)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] => C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
HKU\S-1-5-21-3773765143-1762522670-3504364941-1000\...\Run: [SacReminderHDDV2N] => C:\ProgramData\OfficeGuardianV2N\reminder\SacReminder.exe [862032 2010-11-18] (Storage Appliance Corp.)
HKU\S-1-5-21-3773765143-1762522670-3504364941-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6564120 2014-06-04] (SUPERAntiSpyware)
Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardMinder Viewer.lnk
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.6.lnk
ShortcutTarget: ImageMixer 3 SE Camera Monitor Ver.6.lnk -> C:\Program Files (x86)\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe (PIXELA CORPORATION)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkpad
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {2B6C10C8-5EC9-4107-BA39-7E45AEF4A2E0} URL =
SearchScopes: HKCU - {3707A5F0-5A75-4210-92B3-C15DB38BB05F} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {457AF9A6-E74D-46E0-8D50-2618AD74994C} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\l4htek0o.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: RivalGaming - C:\Users\admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\links@rivalgaming.com [2012-07-20]
FF Extension: VideoDownloadConverter - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\l4htek0o.default\Extensions\4zffxtbr-bs@VideoDownloadConverter_4z.com [2014-05-21]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-07-13]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012-03-06]
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 CFUACProxy_officeguardianv2n; C:\ProgramData\OfficeGuardianV2N\UACProxy.exe [83792 2010-11-18] (Storage Appliance Corp.)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [93032 2010-04-07] (Lenovo Group Limited)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [199272 2010-07-15] (Realtek Semiconductor)
R2 SacNetAgentService_C57C4F854F53; C:\ProgramData\OfficeGuardianV2N\Reminder\SacNetAgent.exe [163664 2010-11-18] (Storage Appliance Corporation)
R2 SUService; c:\Program Files (x86)\Lenovo\System Update\SUService.exe [28672 2010-03-15] (Lenovo Group Limited) [File not signed]
R2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [61440 2008-01-10] (Ulead Systems, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-10-02] (AVG Technologies)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R2 smihlp; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13840 2009-03-13] (UPEK Inc.)
R1 TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [13104 2010-08-24] ()
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [12728 2009-09-29] ()
R3 usbsmi; C:\Windows\System32\DRIVERS\SMIksdrv.sys [205952 2009-11-23] (SMI)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 PCDSRVC{127174DC-C366ED8B-06020101}_0; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]
S3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-20 08:13 - 2014-07-20 08:13 - 01080320 _____ (Farbar) C:\Users\admin\Downloads\FRST.exe
2014-07-15 20:20 - 2014-07-15 20:20 - 00000773 _____ () C:\Users\admin\Desktop\attach.zip
2014-07-14 21:37 - 2014-07-15 21:15 - 00009420 _____ () C:\Users\admin\Desktop\aswMBR.txt
2014-07-14 21:37 - 2014-07-15 21:15 - 00000512 _____ () C:\Users\admin\Desktop\MBR.dat
2014-07-14 20:30 - 2014-07-15 20:14 - 00001190 _____ () C:\Users\admin\Desktop\attach.txt
2014-07-14 20:27 - 2014-07-14 19:28 - 00688992 ____R (Swearware) C:\Users\admin\Desktop\dds.com
2014-07-14 20:26 - 2014-07-14 20:08 - 05185536 _____ (AVAST Software) C:\Users\admin\Desktop\aswMBR.exe
2014-07-14 20:08 - 2014-07-14 20:08 - 05185536 _____ (AVAST Software) C:\Users\admin\Downloads\aswMBR.exe
2014-07-14 19:28 - 2014-07-14 19:28 - 00688992 _____ (Swearware) C:\Users\admin\Downloads\dds.com
2014-07-14 19:25 - 2014-07-14 19:25 - 00000956 _____ () C:\Users\admin\Desktop\ERUNT.lnk
2014-07-14 19:25 - 2014-07-14 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
2014-07-14 19:25 - 2014-07-14 19:25 - 00000000 ____D () C:\Program Files (x86)\ERUNT
2014-07-14 19:22 - 2014-07-14 19:20 - 00791393 _____ (Lars Hederer ) C:\Users\admin\Desktop\erunt-setup.exe
2014-07-14 19:20 - 2014-07-14 19:20 - 00791393 _____ (Lars Hederer ) C:\Users\admin\Downloads\erunt-setup.exe
2014-07-13 13:10 - 2014-07-13 13:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-13 11:30 - 2014-07-02 01:29 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-13 11:30 - 2014-07-02 01:21 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-13 11:30 - 2014-07-02 01:21 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-13 11:30 - 2014-07-02 01:20 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-13 11:29 - 2014-07-13 11:30 - 00004158 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b15.log
2014-07-13 10:32 - 2014-07-13 10:32 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-13 10:32 - 2014-05-30 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-13 10:32 - 2014-05-30 04:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-13 10:32 - 2014-05-30 04:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-13 10:32 - 2014-05-30 04:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-13 10:32 - 2014-05-30 04:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-13 10:32 - 2014-05-30 04:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-13 10:32 - 2014-05-30 04:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-13 10:32 - 2014-05-30 03:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-13 10:30 - 2014-06-05 10:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-13 10:30 - 2014-06-05 10:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-13 10:30 - 2014-06-05 10:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-13 10:20 - 2014-06-29 22:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-13 10:19 - 2014-06-29 22:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-13 10:19 - 2014-06-20 16:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-13 10:19 - 2014-06-20 15:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-13 10:19 - 2014-06-18 21:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-13 10:19 - 2014-06-18 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-13 10:19 - 2014-06-18 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-13 10:19 - 2014-06-18 20:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-13 10:19 - 2014-06-18 20:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-13 10:19 - 2014-06-18 20:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-13 10:19 - 2014-06-18 20:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-13 10:19 - 2014-06-18 20:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-13 10:19 - 2014-06-18 20:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-13 10:19 - 2014-06-18 20:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-13 10:19 - 2014-06-18 20:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-13 10:19 - 2014-06-18 20:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-13 10:19 - 2014-06-18 20:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-13 10:19 - 2014-06-18 20:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-13 10:19 - 2014-06-18 20:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-13 10:19 - 2014-06-18 20:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-13 10:19 - 2014-06-18 20:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-13 10:19 - 2014-06-18 19:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-13 10:19 - 2014-06-18 19:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-13 10:19 - 2014-06-18 19:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-13 10:19 - 2014-06-18 19:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-13 10:19 - 2014-06-18 19:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-13 10:19 - 2014-06-18 19:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-13 10:19 - 2014-06-18 19:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-13 10:19 - 2014-06-18 19:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-13 10:19 - 2014-06-18 19:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-13 10:19 - 2014-06-18 19:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-13 10:19 - 2014-06-18 19:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-13 10:19 - 2014-06-18 19:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-13 10:19 - 2014-06-18 19:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-13 10:19 - 2014-06-18 19:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-13 10:19 - 2014-06-18 19:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-13 10:19 - 2014-06-18 19:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-13 10:19 - 2014-06-18 19:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-13 10:19 - 2014-06-18 19:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-13 10:19 - 2014-06-18 19:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-13 10:19 - 2014-06-18 19:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-13 10:19 - 2014-06-18 19:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-13 10:19 - 2014-06-18 19:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-13 10:19 - 2014-06-18 19:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-13 10:19 - 2014-06-18 18:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-13 10:19 - 2014-06-18 18:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-13 10:19 - 2014-06-18 18:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-13 10:19 - 2014-06-18 18:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-13 10:19 - 2014-06-18 18:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-13 10:19 - 2014-06-18 18:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-13 10:19 - 2014-06-18 18:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-13 10:19 - 2014-06-18 18:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-13 10:19 - 2014-06-18 18:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-13 10:19 - 2014-06-18 18:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-13 10:19 - 2014-06-18 18:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-13 10:19 - 2014-06-18 18:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-13 10:19 - 2014-06-18 18:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-13 10:19 - 2014-06-18 18:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-13 10:19 - 2014-06-17 22:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-13 10:19 - 2014-06-17 21:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-13 10:19 - 2014-06-17 21:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-13 10:19 - 2014-06-06 06:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-13 10:19 - 2014-06-06 05:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-13 10:19 - 2014-05-30 02:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-12 19:18 - 2014-07-12 19:49 - 00000000 ____D () C:\Users\admin\Desktop\mbar
2014-07-12 19:18 - 2014-07-12 19:49 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-07-12 19:15 - 2014-07-12 19:12 - 14349744 _____ (Malwarebytes Corp.) C:\Users\admin\Desktop\mbar-1.07.0.1012.exe
2014-07-12 19:12 - 2014-07-12 19:12 - 14349744 _____ (Malwarebytes Corp.) C:\Users\admin\Downloads\mbar-1.07.0.1012.exe
2014-07-12 18:52 - 2014-07-12 18:53 - 00000085 _____ () C:\Windows\wininit.ini
2014-07-12 15:09 - 2014-07-12 15:19 - 00000000 ____D () C:\ComboFix
2014-07-12 14:54 - 2014-07-12 14:52 - 01016261 _____ (Thisisu) C:\Users\admin\Desktop\JRT.exe
2014-07-12 14:53 - 2014-07-12 14:52 - 01016261 _____ (Thisisu) C:\Users\admin\Downloads\JRT.exe
2014-07-12 13:04 - 2014-07-20 08:16 - 00000000 ____D () C:\Users\admin\Desktop\FRST-OlderVersion
2014-07-12 12:56 - 2014-07-13 11:25 - 00004802 _____ () C:\Windows\PFRO.log
2014-07-11 22:52 - 2014-07-20 06:01 - 00252315 _____ () C:\Windows\WindowsUpdate.log
2014-07-11 22:33 - 2014-07-20 05:17 - 00000336 _____ () C:\Windows\setupact.log
2014-07-11 22:33 - 2014-07-11 22:33 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-11 22:23 - 2014-07-11 22:23 - 00000833 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-11 22:23 - 2014-07-11 22:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-07-11 22:23 - 2014-07-11 22:23 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-10 22:42 - 2014-07-12 18:54 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-10 22:42 - 2014-07-12 18:53 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-10 21:52 - 2014-07-10 21:52 - 00000000 ____D () C:\SUPERDelete
2014-07-10 21:48 - 2014-07-10 21:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task da46279b-4a98-420f-933d-ee03bb02b2b1.job
2014-07-10 21:48 - 2014-07-10 21:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task c6675572-512e-43c2-b0cc-dfb9efd7f5e0.job
2014-07-10 21:48 - 2014-07-10 21:48 - 00000000 ____D () C:\Users\admin\AppData\Roaming\SUPERAntiSpyware.com
2014-07-10 21:46 - 2014-07-10 22:07 - 00001976 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-07-10 21:46 - 2014-07-10 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-07-10 21:46 - 2014-07-10 21:48 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-07-10 21:46 - 2014-07-10 21:46 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-07-10 21:44 - 2014-07-10 21:40 - 04812672 _____ (Piriform Ltd) C:\Users\admin\Desktop\ccsetup415.exe
2014-07-10 21:43 - 2014-07-10 21:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\admin\Desktop\spybot-2.4.exe
2014-07-10 21:43 - 2014-07-10 21:32 - 19998520 _____ (SUPERAntiSpyware) C:\Users\admin\Desktop\SUPERAntiSpyware.exe
2014-07-10 21:40 - 2014-07-10 21:40 - 04812672 _____ (Piriform Ltd) C:\Users\admin\Downloads\ccsetup415.exe
2014-07-10 21:38 - 2014-07-10 21:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\admin\Downloads\spybot-2.4.exe
2014-07-10 21:32 - 2014-07-10 21:32 - 19998520 _____ (SUPERAntiSpyware) C:\Users\admin\Downloads\SUPERAntiSpyware.exe
2014-07-10 21:15 - 2014-07-10 21:15 - 01062136 _____ (Bleeping Computer, LLC) C:\Users\admin\Desktop\rkill64.exe
2014-07-10 21:01 - 2014-07-10 21:21 - 00001420 _____ () C:\Users\admin\Desktop\Rkill.txt
2014-07-10 21:01 - 2014-07-10 21:00 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Desktop\rkill.exe
2014-07-10 21:00 - 2014-07-10 21:00 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Downloads\rkill.exe
2014-07-10 20:59 - 2014-07-10 20:57 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Desktop\rkill.com
2014-07-10 20:57 - 2014-07-10 21:00 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Downloads\rkill.com
2014-07-10 20:00 - 2014-07-10 20:00 - 00000000 ____D () C:\Windows\pss
2014-07-10 19:44 - 2014-07-10 19:43 - 00929416 _____ (CNET Download.com) C:\Users\admin\Desktop\cbsidlm-cbsi188-Junkware_Removal_Tool-SEO-75910255.exe
2014-07-10 19:43 - 2014-07-10 19:43 - 00929416 _____ (CNET Download.com) C:\Users\admin\Downloads\cbsidlm-cbsi188-Junkware_Removal_Tool-SEO-75910255.exe
2014-07-08 20:12 - 2014-07-08 20:14 - 00036020 _____ () C:\Users\admin\Desktop\Addition.txt
2014-07-08 20:00 - 2014-07-20 08:17 - 00016413 _____ () C:\Users\admin\Desktop\FRST.txt
2014-07-08 19:58 - 2014-07-20 08:18 - 00000000 ____D () C:\FRST
2014-07-08 19:56 - 2014-07-20 08:16 - 02089984 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-07-08 19:53 - 2014-07-08 19:53 - 02084352 _____ (Farbar) C:\Users\admin\Downloads\FRST64.exe
2014-07-08 19:19 - 2014-07-08 19:18 - 01348263 _____ () C:\Users\admin\Desktop\adwcleaner_3.215.exe
2014-07-08 19:18 - 2014-07-08 19:18 - 01348263 _____ () C:\Users\admin\Downloads\adwcleaner_3.215.exe
2014-07-08 19:15 - 2014-07-06 15:54 - 04707328 _____ () C:\Users\admin\Desktop\RogueKiller.exe
2014-07-06 21:04 - 2014-07-12 14:58 - 05218570 ____R (Swearware) C:\Users\admin\Desktop\ComboFix.exe
2014-07-06 16:05 - 2014-07-20 08:14 - 00000000 ____D () C:\Users\admin\AppData\Local\CrashDumps
2014-07-06 16:04 - 2014-07-06 16:05 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-06 10:00 - 2014-07-06 11:36 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Luqyva
2014-07-06 09:50 - 2014-07-20 07:47 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-06 09:47 - 2014-07-06 09:47 - 00001153 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-06 09:38 - 2014-07-06 09:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-06 09:37 - 2014-07-12 19:18 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-06 09:37 - 2014-07-06 09:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-06 09:37 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-06 09:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-06 08:57 - 2014-07-06 08:57 - 00000000 ____D () C:\found.000
2014-07-05 21:46 - 2014-07-06 07:55 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Geyhar
2014-07-05 18:07 - 2014-07-05 18:08 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Ikysid
2014-07-05 15:21 - 2014-07-05 18:06 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Suukyw
==================== One Month Modified Files and Folders =======
2014-07-20 08:18 - 2014-07-08 20:00 - 00016413 _____ () C:\Users\admin\Desktop\FRST.txt
2014-07-20 08:18 - 2014-07-08 19:58 - 00000000 ____D () C:\FRST
2014-07-20 08:16 - 2014-07-12 13:04 - 00000000 ____D () C:\Users\admin\Desktop\FRST-OlderVersion
2014-07-20 08:16 - 2014-07-08 19:56 - 02089984 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-07-20 08:15 - 2010-12-18 13:11 - 00000528 _____ () C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2014-07-20 08:14 - 2014-07-06 16:05 - 00000000 ____D () C:\Users\admin\AppData\Local\CrashDumps
2014-07-20 08:13 - 2014-07-20 08:13 - 01080320 _____ (Farbar) C:\Users\admin\Downloads\FRST.exe
2014-07-20 08:10 - 2010-12-18 13:11 - 00000382 _____ () C:\Windows\Tasks\SystemToolsDailyTest.job
2014-07-20 07:47 - 2014-07-06 09:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-20 07:33 - 2012-04-18 19:06 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-20 07:13 - 2014-07-11 22:52 - 00252315 _____ () C:\Windows\WindowsUpdate.log
2014-07-20 05:29 - 2009-07-14 00:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-20 05:29 - 2009-07-14 00:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-20 05:21 - 2011-11-06 16:06 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A5F8349E-1752-4697-865D-471CF82211BC}
2014-07-20 05:17 - 2014-07-11 22:33 - 00000336 _____ () C:\Windows\setupact.log
2014-07-20 05:17 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-15 21:15 - 2014-07-14 21:37 - 00009420 _____ () C:\Users\admin\Desktop\aswMBR.txt
2014-07-15 21:15 - 2014-07-14 21:37 - 00000512 _____ () C:\Users\admin\Desktop\MBR.dat
2014-07-15 20:20 - 2014-07-15 20:20 - 00000773 _____ () C:\Users\admin\Desktop\attach.zip
2014-07-15 20:14 - 2014-07-14 20:30 - 00001190 _____ () C:\Users\admin\Desktop\attach.txt
2014-07-14 20:08 - 2014-07-14 20:26 - 05185536 _____ (AVAST Software) C:\Users\admin\Desktop\aswMBR.exe
2014-07-14 20:08 - 2014-07-14 20:08 - 05185536 _____ (AVAST Software) C:\Users\admin\Downloads\aswMBR.exe
2014-07-14 19:28 - 2014-07-14 20:27 - 00688992 ____R (Swearware) C:\Users\admin\Desktop\dds.com
2014-07-14 19:28 - 2014-07-14 19:28 - 00688992 _____ (Swearware) C:\Users\admin\Downloads\dds.com
2014-07-14 19:26 - 2012-03-18 15:58 - 00000000 ____D () C:\Windows\ERDNT
2014-07-14 19:25 - 2014-07-14 19:25 - 00000956 _____ () C:\Users\admin\Desktop\ERUNT.lnk
2014-07-14 19:25 - 2014-07-14 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
2014-07-14 19:25 - 2014-07-14 19:25 - 00000000 ____D () C:\Program Files (x86)\ERUNT
2014-07-14 19:20 - 2014-07-14 19:22 - 00791393 _____ (Lars Hederer ) C:\Users\admin\Desktop\erunt-setup.exe
2014-07-14 19:20 - 2014-07-14 19:20 - 00791393 _____ (Lars Hederer ) C:\Users\admin\Downloads\erunt-setup.exe
2014-07-14 17:52 - 2012-05-06 11:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-13 15:38 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-07-13 13:11 - 2014-07-13 13:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-13 11:30 - 2014-07-13 11:29 - 00004158 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b15.log
2014-07-13 11:30 - 2014-01-01 20:29 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-13 11:30 - 2013-09-06 18:53 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-13 11:25 - 2014-07-12 12:56 - 00004802 _____ () C:\Windows\PFRO.log
2014-07-13 11:25 - 2009-07-14 00:45 - 00335184 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-13 11:23 - 2014-05-07 20:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-13 11:23 - 2009-07-14 03:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-13 11:23 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-13 11:23 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-13 10:33 - 2012-04-18 19:06 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-13 10:33 - 2012-04-18 19:06 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-13 10:33 - 2011-05-16 18:36 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-13 10:32 - 2014-07-13 10:32 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-13 10:25 - 2013-08-15 00:03 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-13 10:08 - 2011-02-03 19:48 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-12 19:49 - 2014-07-12 19:18 - 00000000 ____D () C:\Users\admin\Desktop\mbar
2014-07-12 19:49 - 2014-07-12 19:18 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-07-12 19:18 - 2014-07-06 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-12 19:12 - 2014-07-12 19:15 - 14349744 _____ (Malwarebytes Corp.) C:\Users\admin\Desktop\mbar-1.07.0.1012.exe
2014-07-12 19:12 - 2014-07-12 19:12 - 14349744 _____ (Malwarebytes Corp.) C:\Users\admin\Downloads\mbar-1.07.0.1012.exe
2014-07-12 18:54 - 2014-07-10 22:42 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-12 18:53 - 2014-07-12 18:52 - 00000085 _____ () C:\Windows\wininit.ini
2014-07-12 18:53 - 2014-07-10 22:42 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-12 15:19 - 2014-07-12 15:09 - 00000000 ____D () C:\ComboFix
2014-07-12 15:18 - 2009-07-13 22:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-12 14:58 - 2014-07-06 21:04 - 05218570 ____R (Swearware) C:\Users\admin\Desktop\ComboFix.exe
2014-07-12 14:52 - 2014-07-12 14:54 - 01016261 _____ (Thisisu) C:\Users\admin\Desktop\JRT.exe
2014-07-12 14:52 - 2014-07-12 14:53 - 01016261 _____ (Thisisu) C:\Users\admin\Downloads\JRT.exe
2014-07-12 12:59 - 2013-10-15 05:40 - 00000000 ____D () C:\AdwCleaner
2014-07-12 12:56 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\registration
2014-07-11 22:33 - 2014-07-11 22:33 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-11 22:29 - 2011-11-05 21:12 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-07-11 22:28 - 2009-07-24 13:29 - 00000000 ____D () C:\Windows\Panther
2014-07-11 22:23 - 2014-07-11 22:23 - 00000833 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-07-11 22:23 - 2014-07-11 22:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-07-11 22:23 - 2014-07-11 22:23 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-10 22:07 - 2014-07-10 21:46 - 00001976 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-07-10 21:52 - 2014-07-10 21:52 - 00000000 ____D () C:\SUPERDelete
2014-07-10 21:48 - 2014-07-10 21:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task da46279b-4a98-420f-933d-ee03bb02b2b1.job
2014-07-10 21:48 - 2014-07-10 21:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task c6675572-512e-43c2-b0cc-dfb9efd7f5e0.job
2014-07-10 21:48 - 2014-07-10 21:48 - 00000000 ____D () C:\Users\admin\AppData\Roaming\SUPERAntiSpyware.com
2014-07-10 21:48 - 2014-07-10 21:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-07-10 21:48 - 2014-07-10 21:46 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-07-10 21:46 - 2014-07-10 21:46 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-07-10 21:40 - 2014-07-10 21:44 - 04812672 _____ (Piriform Ltd) C:\Users\admin\Desktop\ccsetup415.exe
2014-07-10 21:40 - 2014-07-10 21:40 - 04812672 _____ (Piriform Ltd) C:\Users\admin\Downloads\ccsetup415.exe
2014-07-10 21:38 - 2014-07-10 21:43 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\admin\Desktop\spybot-2.4.exe
2014-07-10 21:38 - 2014-07-10 21:38 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\admin\Downloads\spybot-2.4.exe
2014-07-10 21:32 - 2014-07-10 21:43 - 19998520 _____ (SUPERAntiSpyware) C:\Users\admin\Desktop\SUPERAntiSpyware.exe
2014-07-10 21:32 - 2014-07-10 21:32 - 19998520 _____ (SUPERAntiSpyware) C:\Users\admin\Downloads\SUPERAntiSpyware.exe
2014-07-10 21:21 - 2014-07-10 21:01 - 00001420 _____ () C:\Users\admin\Desktop\Rkill.txt
2014-07-10 21:15 - 2014-07-10 21:15 - 01062136 _____ (Bleeping Computer, LLC) C:\Users\admin\Desktop\rkill64.exe
2014-07-10 21:00 - 2014-07-10 21:01 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Desktop\rkill.exe
2014-07-10 21:00 - 2014-07-10 21:00 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Downloads\rkill.exe
2014-07-10 21:00 - 2014-07-10 20:57 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Downloads\rkill.com
2014-07-10 20:57 - 2014-07-10 20:59 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\admin\Desktop\rkill.com
2014-07-10 20:00 - 2014-07-10 20:00 - 00000000 ____D () C:\Windows\pss
2014-07-10 19:43 - 2014-07-10 19:44 - 00929416 _____ (CNET Download.com) C:\Users\admin\Desktop\cbsidlm-cbsi188-Junkware_Removal_Tool-SEO-75910255.exe
2014-07-10 19:43 - 2014-07-10 19:43 - 00929416 _____ (CNET Download.com) C:\Users\admin\Downloads\cbsidlm-cbsi188-Junkware_Removal_Tool-SEO-75910255.exe
2014-07-08 20:14 - 2014-07-08 20:12 - 00036020 _____ () C:\Users\admin\Desktop\Addition.txt
2014-07-08 19:53 - 2014-07-08 19:53 - 02084352 _____ (Farbar) C:\Users\admin\Downloads\FRST64.exe
2014-07-08 19:18 - 2014-07-08 19:19 - 01348263 _____ () C:\Users\admin\Desktop\adwcleaner_3.215.exe
2014-07-08 19:18 - 2014-07-08 19:18 - 01348263 _____ () C:\Users\admin\Downloads\adwcleaner_3.215.exe
2014-07-08 19:00 - 2013-09-02 06:28 - 00000000 ____D () C:\Users\admin\AppData\Local\Avg2013
2014-07-08 19:00 - 2013-09-02 06:28 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-08 18:58 - 2013-09-02 06:32 - 00000000 ____D () C:\ProgramData\AVG2013
2014-07-08 18:57 - 2013-09-02 06:32 - 00000000 ____D () C:\$AVG
2014-07-06 18:50 - 2012-03-18 15:57 - 00000000 ____D () C:\Qoobox
2014-07-06 16:05 - 2014-07-06 16:04 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-06 15:54 - 2014-07-08 19:15 - 04707328 _____ () C:\Users\admin\Desktop\RogueKiller.exe
2014-07-06 11:36 - 2014-07-06 10:00 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Luqyva
2014-07-06 09:48 - 2012-03-18 10:53 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Malwarebytes
2014-07-06 09:47 - 2014-07-06 09:47 - 00001153 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-06 09:47 - 2014-07-06 09:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-06 09:38 - 2014-07-06 09:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-06 09:37 - 2012-03-18 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-06 09:36 - 2013-10-15 05:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-07-06 08:57 - 2014-07-06 08:57 - 00000000 ____D () C:\found.000
2014-07-06 07:59 - 2010-12-18 13:11 - 00003448 _____ () C:\Windows\System32\Tasks\PCDEventLauncher
2014-07-06 07:59 - 2010-12-18 13:11 - 00000000 ____D () C:\ProgramData\PCDr
2014-07-06 07:55 - 2014-07-05 21:46 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Geyhar
2014-07-05 18:08 - 2014-07-05 18:07 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Ikysid
2014-07-05 18:06 - 2014-07-05 15:21 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Suukyw
2014-07-04 18:34 - 2009-07-14 01:08 - 00032594 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-02 01:29 - 2014-07-13 11:30 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-02 01:21 - 2014-07-13 11:30 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-02 01:21 - 2014-07-13 11:30 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-02 01:20 - 2014-07-13 11:30 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-06-29 22:09 - 2014-07-13 10:20 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-29 22:04 - 2014-07-13 10:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-20 16:14 - 2014-07-13 10:19 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-20 15:39 - 2014-07-13 10:19 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
Some content of TEMP:
====================
C:\Users\admin\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-13 15:19
==================== End Of Log ============================